CWE-459
4 CVEs of this weakness class.
- CVE-2026-3304HIGH 7.5Real · low riskEPSS 1%
Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.
- CVE-2025-60730HIGH 7.6Real · low riskEPSS 0%
PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function
- CVE-2026-53867MED 4.3EPSS 0%
Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated URLs, allowing unauthorized retrieval of user-uploaded content.
- CVE-2026-7639HIGH 7.8Real · low riskEPSS 0%
Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MMU mapping logic by a malicious code could lead to incomplete cleanup of an internal driver state, allowing for future unauthorized access to the contents of the physical memory.